ilvalle
ad3c69155b
fix few urllib.urlencode, close #1841
2018-02-04 09:58:16 +01:00
Roald Osinga
9bf8ca9c3b
made cas_provider response py3 compatible
2018-01-05 11:49:20 +01:00
mdipierro
4a2a02d1fe
fixed display of computed fields
2017-12-02 12:52:15 -06:00
mdipierro and GitHub
551c19bcaf
Merge pull request #1761 from josedesoto/issue/update_role_on_update_profile
...
Update groups on edit profile
2017-11-13 21:14:02 -06:00
Leonel Câmara
925f928843
Copy all CRYPT attributes thanks @abastardi
2017-11-08 11:53:29 +00:00
Leonel Câmara
228d3c41b6
Fixes #1800
2017-11-07 23:34:35 +00:00
Jose de Soto and GitHub
5f4c47729b
Removed a tab and replaced by spaces
2017-09-21 10:17:17 +02:00
Jose de Soto
e8cf50326d
When profile is updated self._update_session_user(user) set session.user_groups to None. self.update_groups() needs to be done.
2017-09-13 11:21:03 +02:00
mdipierro
213c4ee7d1
fixed use of whitespaces
2017-08-01 10:26:33 -05:00
mdipierro and GitHub
7088b74d42
Merge pull request #1705 from josedesoto/enhancement/1557
...
Enhancement/1557
2017-08-01 09:46:55 -05:00
Jose de Soto
d5167f2ed6
change_password_url parameter for alternate login methods
2017-07-31 19:00:24 +02:00
Jose de Soto
1014d3e86e
new parameter to auto create or not users with alternate login methods
2017-07-31 18:33:15 +02:00
Jan Kotyz
19efbfecfa
Fixes 1700
2017-07-27 11:27:41 +02:00
Leonel Câmara
b7b8a009f2
Fixes #1680
2017-07-14 20:17:30 +01:00
mdipierro and GitHub
453123a8ed
Merge pull request #1652 from BuhtigithuB/improve/pep8-tools-py
...
Enhance tools.py PEP8 compliancy
2017-07-10 14:11:11 -05:00
mdipierro
f657b42f65
fixed undefined variable
2017-07-02 01:34:05 -05:00
mdipierro
1c0b498880
fixed undefined variable
2017-07-02 01:32:25 -05:00
Richard Vézina
583d106104
Fix docstring py3 compatibility issues print -> print()
2017-06-21 11:33:00 -04:00
Richard Vézina
7ada2cf89a
Enhance tools.py PEP8 compliancy
2017-06-21 11:27:54 -04:00
mdipierro
0674111129
fixes #1579 , thanks Nico
2017-06-20 14:29:47 -05:00
mdipierro
18b755b8da
fixed #1583 , thanks matclab
2017-06-20 14:24:35 -05:00
Leonel Câmara
376c12a225
Fixes #1628
2017-06-05 23:35:41 +01:00
mdipierro and GitHub
baa129f871
Merge pull request #1527 from leonelcamara/authapi2
...
Auth refactor
2017-05-01 09:13:18 -05:00
BrenBarn
86a2c529b9
Change to modify Service instead of adding FlexibleService
2017-01-31 14:13:43 -08:00
BrenBarn
55592e7c6e
Add FlexibleService, which allows @service-style methods that accept varargs
2017-01-31 11:48:28 -08:00
Martin Doucha
e7cab3b975
Add Auth and Crud messages when updating language files
2016-12-20 18:54:20 +01:00
Leonel Câmara
bf5ec0d7cf
Fixed a long standing bug in login_user which was using 'password' instead of settings.password_field
...
Fixes #636
2016-11-20 19:38:21 +00:00
Giuseppe Chiesa
2c70a858f1
implemented base support for CASv3
2016-11-17 13:30:11 +01:00
mdipierro and GitHub
091d9c74b0
Merge pull request #1525 from michele-comitini/confirm_registration_redirect_fix
...
keep the _next while doing the redirect
2016-11-14 08:27:39 -06:00
Leonel Câmara
02f0bdb8d3
Auth refactor, extracted many methods into a base class for more generic auth mechanisms.
...
Partially addresses #1526
Includes a solution for IS_LOWER and IS_UPPER validator problems I mentioned in #1353
2016-11-05 16:37:22 +00:00
Michele Comitini
6b1225da02
keep the _next while doing the redirect
2016-11-04 09:59:49 +01:00
Mathieu Clabaut
2d4817841f
Allow for firstname and lastname in verify_email message
2016-11-01 11:31:01 +01:00
niphlod
40d6a72b90
fixes #1455
2016-09-21 22:35:04 +02:00
kelson
fe058bf817
fixed auth.add_membership succeeding with invalid group_id/user_id
2016-08-17 17:17:34 -04:00
Giovanni Barillari
0528a347b3
Updated pyDAL to 16.08
2016-08-13 15:38:55 +02:00
mdipierro
35eaba1096
removed duplicated code, using pydal's _compat.py
2016-08-01 03:39:22 -05:00
niphlod
cae10a68c0
fixed most of py3 warnings, output is much cleaner this way
2016-07-18 23:45:28 +02:00
Jason Bohrer and GitHub
0c4d254a9c
Changed tuple to list
...
The comparison between parts[1:3] and ('', host) would return false because a list and a tuple were being compared.
2016-07-01 13:26:23 -04:00
mdipierro
d9c2f778ee
fixed auth next open redirect
2016-07-01 02:22:15 -05:00
Th3R3p0
d95acb6897
Fixed open redirect security vulnerability. The previous filter searched for two forward slashes "//" in the "_next” parameter and if the two forward slashes were found it would check the URI and determine if the hostname matched the hostname of the web server. If not, it would change the next variable to the None. However, browsers don't require two forward slashes. As a feature, browsers accept typos such as http:google.com or http:/google.com and redirect to http://google.com . This can be used to leverage an open redirect attack even with the current filter. This commit fixes the open redirect vulnerability in the _next get parameter. Thanks to jnbrex for helping debug/write the patch for this vulnerability.
2016-06-30 17:24:47 -04:00
Alex Artigues
f87c3e260c
Fix next redirect if only one / exists
2016-06-29 20:54:13 -04:00
ilvalle
48209f5bdf
fix compileapp
2016-06-13 20:20:49 +02:00
ilvalle
7259516627
fix tools
2016-06-13 20:20:44 +02:00
mdipierro
a18e0e489f
why is session.forget not callable in tests?
2016-06-12 21:08:33 -05:00
mdipierro
dfb0129f09
do not forget a missing session
2016-06-12 20:55:16 -05:00
mdipierro
f4a353960b
merged conflicts
2016-06-12 19:59:58 -05:00
Chen Rotem Levy
9877ad5155
fix in_base for base='/'
...
If the base directory already ends with '/' the test failed.
It failed because we added an extra '/' to make sure that '/foobar' is
not under '/foo', so ask '/foobar/'.startswith('/foo/').
Whoever when we have the base already start with '/' we might test:
'/foo/bar/'.startwith('/foo//'), and give a false negative. We
shouldn't have this case, because we normalized the path, but in the
case of the root directory ('/') even a normalized path ends with '/',
and thus when base='/' this function failed.
Some re-factoring was needed to make this base testable.
2016-06-11 12:19:16 +03:00
Chen Rotem Levy
e020395bdc
apply pull request #1313
...
This should have resolved security issue#1261 -- gluon.tools.Expose
symlinks, however it does not deal well with the case where the base
exposed directory is '/'
2016-06-11 11:20:23 +03:00
zvolsky
225a286162
revert wiki to earlier (properly working) state
2016-06-07 15:10:03 +02:00
ilvalle
db8306b5c4
fix iteritems, enabled test_cache & test_dal for 3.5
2016-06-02 17:21:36 +02:00